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To 3: 

Stan: 

Recent events tend to 
have overtaken parts of the 
attached memorandum on 
"Compartmentation. " The 
conversation you and I had on 
this issue on Wednesday, 

23 August, is one of those 
events. I do believe, however, 
it is worth your time to read 
this document. 
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John F. Blake 
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AUG W' 


MEMORANDUM FOR: 
VIA* 

FROM: 

SUBJECT: 


Director of Central Intelligence 
Deputy Director of Central Intelligence 
John F. Blake 

Deputy Director for Administration 
Comp ar troen t a t i on 


1. (AIUO) Action Requested : Hone; for your information 
only. I have reviewed your memorandum on this subject and will 
attempt to provide you with a perspective on where we now 
appear to stand in the compartmentation arena. 


2. (C) 


Background : 



ommented, in effect, 25X1A 
the compartment at ion 


that there were too many 0 

pot and that we suffered from a lack of central management and 
common standards. He focused on the fact that collectors, with 
their own vested interests, were establishing compartments and 
writing theiT own implementation rules. In the past year we 
have seen two steps that, hopefully, will take us a long way 
toward regularizing that situation. In June 1978 DCID 1/19 
established uniform procedures for the handling of Sensitive 
Compartmented Information (SCI). Secondly, a proposed DCID on 
compartmentation is currently being floated with the HFIB 
members. When passed it will, in keeping with your desires, 
establish the DCI Security Committee as the "honest broker" who 
can recommend to you when compartments should be created, con- 
tinued or closed out. 


3. (U) Executive Order 12065 decrees that all special 

access programs which involve sources and methods must be 
approved in writing by you. Benchmarks which must be satisfied 
to qualify for compartmentation status include: a) the normal 
management and safeguarding procedures are not sufficient to 
limit need- to- know ot access, b) the number of persons who will 
need access will be reasonably small and commensurate with the 
objective of providing extra protection for the information 
involved, and c) the special access controls balance the need to 
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protect the information against the full spectrum of needs 
to use the information. All such programs must he reviewed 
regularly and will automatically terminate in five years 
unless fully rejustified. Additionally, all extant special 25X1 A 

access programs must be revalidated prior to 1 June 1970 . 

4. (C) The DC I Security Committee has an initiative 
underway with its current review of the MRP Compartmentation 
Review. This review, just getting off the ground, wil^^of 
course, review the General Tighe concern over use of H^|| 

25X1 A project names in the TK world, but will use this exer^^^^^^^s 

its first attempt to revalidate projects and the system 

itself as special access program^^ising as a baseline the 
standards imposed by the Executive Order. 

5. (C) Additionally, the DC I Security Committee has 
received recent confirmation from Collection Tasking that they 
are ready to start the dialogue on determining what space 
project can be decompartmented . As we develop what SIGINT and 
COMIREX feel can be taken out from special system protection 
we would propose to confer with intelligence consumers to test 
the adequacy and completeness of the committees’ judgments. We 
believe the resultant product of this joint effort will help to 
satisfy the balance required of customer needs versus collection 
sensitivities, fulfill the charge of Presidential Directive- 57 
to selectively relax space product controls and, as a bonus, 

lay firm foundations for the later revalidation program of the 
COMINT and TALENT -KEYHOLE special access programs. 

6. (U) You also noted that you hoped that rules would be 
established to ensure that you are kept posted of bigot lists. 

We are preparing a memorandum on the subject of bigot lists for 
you as a result of our review of the DBO ’’Blue Border" documents. 

In it you will find that we argue for comp ar tmen t a t i on only for 
sensitive activities which involve a relatively greater volume 
of activity and personnel. The point expressed is that, if any 
activity is quite small and highly sensitive, it can be provided 
better protection through a bigot list than by formally compart - 
menting it. In those cases we believe security is better served 
if the activity manager, whether it be the DDQ, Cl Staff, or a 
Department of Defense entity, deals directly with you on the 
management of the bigot list approach with no centralized system 
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liforaatlonBranch An instruction will be prepared indi- 
StiM you? Interest In personally monitoring bigot list 

activity. 


'/ 3 / lo'iti F. Elcr>o 

Jolm V. Blake 
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1 1 AUG 1978 


MEMORANDUM FOR: Deputy Director for Administration 
FROM: Director of Central Intelligence 


SUBJECT: Compartmentation 


25X1A 

25X1A 


25X6 

25X6 


1 . Further to the conversation you, and I had 

on security and com partmentation, I have jus^e^ewea a memo of 
last September from just before he left the Security 
Committee ("Community Security Needs and Problems," 29 September 
1977, SECOM-D-282) . In it he had the following paragraph: 


"The Intelligence Community's special security control 
systems are conspicuous for their lack of central management 
and common standards. The perception of abuse in this area 
(whether or not well founded) has prompted pleas for change 
from many Community agencies. But, we are just now beginning 
to take tentative steps towards some sort of standardized 
procedures. A basic problem is that there are too many 
Community components involved in the subject. Another funda- 
mental problem, and the one that may well cause the most 
suspicion on the part of consumers, is that the collectors who 
argue the need for compartments to begin with are also the 
ones who write the implementation rules, with their programs 
and procedures subject effectually only to review by themselves. 
Current approaches to the subject favor those with a vested 
interest in the status quo. Arguments are often made for the 
continuation of a system not so much because it is currently jus- 
tified, but because of history. The COMINT compartment, for 
example, is very much in need of thorough review and revision 
to bring it into line with 1977 circumstances. Its nararrtf 



new 

security classification provides, for the first 
time, national level standards for compartments, and requires 
that all existing ones be measured against those standards and 
continued only where they are satisfied. Under those standards. 
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the DC I must personally approve all compartments in writing. 

I believe he must be able to look to a single Community 
focal point to coordinate the varying inputs he will need 
to judge the appropriateness of a compartment. Collectors 
obviously need to be able to argue their case for protection. 
Consumers need to be able to argue their case on utility of 
data. Someone needs to assess proposed systems and advise 
whether the desired security objectives can reasonably be 
satisfied in the real world. Then, there needs to be a 
Community focal point to manage the approved compartments by 
keeping track of authorized accesses and fielding complaints 
and suggestions about programs." 

2. If I understand it, the Security Committee is now working on 
implementing directives for the new security order which will move 
in the directions was talking about here. Essentially, I hope 
that I will confirm or cancel existing compartmentation, possibly 
setting up new compartments and establishing rules to ensure that I'm 
kept posted of bigot lists, etc., that are created outside the 
compartmentation area.Is that correct, and are we going to take care 
of these points that raised? 

STAl^d TURNER 



cc: Deputy Director for 
Resource Management 
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DIRECTOR OF CENTRAL INTELLIGENCE 

Security Committee 



SECOM-D-282 
29 September 1977 

25X1 A 

MEMORANDUM 

FROM 

SUBJECT : Community Security Needs and Problems (U) 


FOR: Acting Deputy to the DC I 
Intelligence Community 


for 


lairman 





1. (FOUO) As I leave the chairmanship of the DCI Security Committee, 
I would like to share some of my thoughts and conclusions on Intelligence 
Community security needs and problems. The needs as I see them focus on 
organization, management, and resources dedicated to Community security 
matters. 

2. (U) Some particularly significant problems that I see needing 
effective resolution are: 

a. (FOUO) Personnel Security Standards. By any reasonable 
test, persons throughout the government (and industry) should meet 
essentially the same standards for access to intelligence infor- 
mation at the same level of classification. The standards, however, 
vary widely. CIA has very stringent ones for its employees. Yet, 
CIA-generated intelligence is disseminated widely to Defense, State, 
and other agencies using lesser standards. Defense, for example, 
grants a Secret clearance on the basis of a non-derogatory National 
Agency Check, and a Top Secret clearance on the same basis if the 
service member has ten or more years satisfactory service. Defense 
permits industry to grant a Confidential clearance without any checks 
at all. I view these as essentially meaningless— they do not affirm 
claimed identity, and they do not show any positive indicators of 
loyalty and trustworthiness. These varying standards are based on 
different concepts of what is a necessary and proper basis for 
granting clearances. A Security Committee working group is con- 
ducting a study to try to determine what is necess ary and desirabl e 
i n^pergonr!eI' ~SU'dgyj ty. l, T7ie‘Vesijlts'ri^hVfe'"l3riiTi 1 arfTy“'^pl~i7:~able~ro 
a’pWrrHyTd“Wv i sToh of DCID 1/14, should give us a good basis for 
proposing better standards throughout the government for access to 
Secret and Top Secret information. But, that is easier said than 
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done. A fairly well-solidified body of opinion more concerned 
with privacy considerations and due process than with good security 
coalesced in recent years behind the proposed revision of Ji.O. 10450 
which sets personnel security standards for Government employees 
generally. I do not believe the Intelli ge nce Communi ty will be able 
to make its views prevail in this arena unTessT it can speak with a 
s j.ngl e vojcej m the subject and be supported at the policy level. 


25X1A 


b. (C) Computer Security. I am quite concerned about the 
security of intelligence informations particularly that which is 
compartmented, in shared ADP systems accessible by persons with 
varying levels of security clearances. The multi-level mode of 
operation of such systems relies too much in my judgment on every- 
thing working exactly as it should. Computer software cannot give 
positive assurances that boundaries between different classification 
and control levels of stored/processed data cannot be violated. The 


business experience with fraud and embezzlement through AUP systems 
suggests that the perpetrators are caught more by accident than by 
effective security precautions built into the equipment and its 
software. I believe there needs to be a greater concentration of 
Community effort in this area, and a single Community focal point to 
identify specific problems and devise coordinated policy to correct 
them. 


c. (C) Compartmentation. The Intelligence Community's special 
security control systems are conspicuous for their lack of central . 
management and common standards. The perception of abuse in this 
area (whether or not well founded) has prompted pleas for change from 
many Community agencies. But, we are just now beginning to take 
tentative steps towards some sort of standardized procedures. A 
basic problem is that there are too many Community components involved 
in the subject. Another fundamental problem, and the one that may well 
cause the most suspicion on the part of consumers, is that the collec- 
tor s who argue the need for compartments to begi n with are al soTfie" 
ones' who write the-.imol pinpnt .ati nn rn j . wTtKtKei r programTlinff 
proceduressubject effectually on! v to reAdewJiv-themse.1 ves . Current 
approaches to the subject favor those with a vested interest in the 
status quo. Arguments are often made for the continuation of a system 
not so much because it is currently justified, but because of history. 
The QQMINT compartment, for example, is very much in need of thorough 
25X6 review and revision to bring it into line with 1977 circumstances. 
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25X6 

25X6 


classification provides, for the first time, national level standards 
f t for compartments, and requires that all existing ones be measured 
against those standards and continued only where they are satisfied. 
Under those standards, th e PCI must personally .approve all compart- 
ments in writing.. I bel i eve*Tie~musTDe^bTe to look to a single 
Community focal point to coordinate the varying inputs he will need 
to judge the appropriateness of a compartment. Collectors obviously 
need to be able to argue their case for protection. Consumers need 
to be able to argue their case on utility of data. Someone needs to 
assess proposed systems and advise whether the desired security objec- 
tives can reasonably be satisfied in the real world. Then, there 
needs to be a Communit y focal lire .. appr oved compart- 
ments by keegjnOH&Ljaf ^A iLt hor J.zad^a^SA-Q 5„an d_.fi el dTnFTompTTfnts 

3. (FOUO) I believe the Security Committee as a staff support element 
for the DCI is the logical focal point for the Community in all security 
matters. Its responsibility for such should be made explicit through charter 
revision, which should simultaneously see that the charters of collection 
committees are changed to state that their security responsibilities are 
advisory to the Security Committee. These changes would have to be accom- 
panied by resource reallocations to give the Security Committee enough 
manpower to enable it to support the DCI's security responsibilities effect- 
ively. C urrent ma nnnwer aiitho£.i.7a±.inris-.&ss£MlaII_v_liniit us to a . collegial 
role, relying on Commun i ty agencies to provide personnel on an additional 
■duty basis to chair functional subcommittees and working groups, and sometimes 
restricting us to the painfully slow evolution of a Community consensus 
before a policy can be developed or revised. With adequate manpower, we 
can serve as a meaningful support component for the DCI and the Community. 

This would involve a capability: (1) to chair with our own people the 
requisite subcommittees (compartmentation, computer security, etc.) and 
working groups (e.g., personnel security standards) and thereby control 
timetables and agenda; (2) to monitor compliance with DCI security directives 
throughout the Community, and (3) to assist Community agencies in the imple- 
mentation of security policy. I believe that failure to establish and 
properly staff a Community focal point for security could result in outside 
entities seeking to fill the vacuum. Community acceptance of an cooperation 
with any coordinating security body will be strongly influenced by the per- 
ception of independence of such body from any single Community agency. 
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4. (U) The above comments notwithstanding, the Security Committee 

has made some significant accomplishments. However, much remains to be 
done. 


25X1 A 
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